YoVDO

Touching the Untouchables - Dynamic Security Analysis of the LTE Control Plane

Offered By: IEEE via YouTube

Tags

Vulnerability Assessment Courses Cybersecurity Courses

Course Description

Overview

Explore a comprehensive analysis of LTE control plane security in this IEEE conference talk. Delve into the dynamic testing of control components in operational Long Term Evolution networks using LTEFuzz, a semi-automated testing tool. Learn about the systematic generation of test cases based on three fundamental security properties derived from LTE standards. Discover 36 previously undisclosed vulnerabilities categorized into five types: improper handling of unprotected initial procedures, crafted plain requests, messages with invalid integrity protection, replayed messages, and security procedure bypass. Examine proof-of-concept attacks demonstrating the impact of these vulnerabilities, including denial of LTE services, SMS spoofing, and eavesdropping on user data traffic. Gain insights into root cause analysis and potential countermeasures for addressing these security issues. Understand the ethical considerations and involvement of cellular carriers in verifying findings within commercial LTE networks.

Syllabus

Intro
LTE communication is everywhere
LTE network architecture
Previous studies and its limitations
Challenges in active network testing
Overview of LTEFuzz
Generating test cases
Executing test cases
Operational networks are complicated
Classifying the problematic behavior
LTEFuzz test environment
Implementation
Findings
Remote de-register attack
Responsible disclosure
Conclusion


Taught by

IEEE Symposium on Security and Privacy

Tags

Related Courses

Computer Security
Stanford University via Coursera
Cryptography II
Stanford University via Coursera
Malicious Software and its Underground Economy: Two Sides to Every Story
University of London International Programmes via Coursera
Building an Information Risk Management Toolkit
University of Washington via Coursera
Introduction to Cybersecurity
National Cybersecurity Institute at Excelsior College via Canvas Network